SAN-101 · Free online · Self-paced

Thinking with AI:
Human Factors for the AI-Augmented Analyst

Your tools now summarise, triage and recommend before you have read a single log line. SAN-101 teaches working cybersecurity analysts the discipline the industry skipped: how to use AI without being used by it — calibrated trust, bias resistance, durable tradecraft and accountable, auditable AI-assisted decisions.

2 days · 09:00–17:00 Free online · personal access link Prerequisites: working security experience On-site UK or virtual classroom

Overview

Who this course is for.

SAN-101 is a practitioner course, not an awareness seminar. It assumes you already do the work — and that AI has already changed how the work reaches you.

SOC Analysts & Incident Responders

You triage AI-enriched alerts, work from AI-generated summaries, and are measured on speed. You need verification protocols that hold under time pressure.

Penetration Testers & Red Teamers

You use AI for recon, reporting and exploit research — and face AI-enabled adversaries. You need to know where AI accelerates you and where it quietly misleads you.

CREST Candidates & Members

You are preparing for CPSA/CRT examinations or maintaining certified status, and want human-factors practice that reflects the AI-shaped environment you actually work in.

Prerequisites

Working experience in a security operations, incident response or testing role. Familiarity with common analyst tooling (SIEM, EDR, ticketing). No programming or data-science background required — this course is about judgement, not model building.

What to bring

A laptop with a modern browser. The free online edition runs entirely in your browser — no account password, no install. Use your own tools for the practice prompts if you wish.

Learning Outcomes

What you will be able to do.

On completion, and evidenced through assessment, you will be able to:

Describe current AI-enabled threat techniques — deepfake social engineering, LLM-assisted reconnaissance and agentic attack chains — and what they change for detection and triage.
Operate AI copilots and LLM-assisted tooling inside a structured verification protocol, including second-channel confirmation and provenance checks.
Recognise automation bias, algorithmic authority and confabulation in live workflow — in yourself and in your team — and apply countermeasures drawn from human factors research.
Design personal and team SOPs for AI-assisted triage, summarisation and reporting that remain auditable end-to-end.
Maintain CREST-relevant core tradecraft through deliberate practice and “AI-shadow” drills, countering skill degradation from cognitive offloading.
Apply ISO/IEC 42001, the NIST AI Risk Management Framework and EU AI Act awareness to everyday analyst decisions, and document AI-assisted conclusions for audit.
Identify where AI must not be used in security workflow — evidential chains, legal thresholds, novel intrusion sets — and justify the boundary.
Investigate a full AI-assisted incident scenario under time pressure, catching injected AI errors, and defend your decisions in a structured debrief.

Curriculum

Five modules. Two days. One discipline.

Every module pairs the technical reality of AI in security with the human factors science that determines whether it helps or harms. Roughly 40% of contact time is hands-on.

Topics

  • AI-enabled social engineering: deepfake voice and video, spear phishing at machine scale, synthetic pretexting
  • LLM-assisted adversary workflow: reconnaissance, phishing infrastructure, malware iteration and evasion
  • Agentic attack chains and machine-speed recon — what compresses, what doesn’t
  • Separating demonstrated capability from marketing: evidence-based threat perception

Exercise

  • Live triage of synthetic vs. genuine social-engineering artefacts — measure your own detection rate, then your team’s
Human factors lens: threat perception under novelty — how availability bias and narrative hype distort analyst priors, and how to recalibrate with base rates.

Topics

  • The AI-augmented SOC stack: copilots, LLM-assisted triage, alert summarisation, detection engineering assistants
  • Prompt-driven investigation: structured querying of logs, pcaps and intel through natural language
  • Failure modes that matter operationally: hallucination, confabulation, sycophancy, silent omission, prompt injection via retrieved content
  • Local vs. cloud models: data handling, evidential integrity and client-confidentiality boundaries

Exercise

  • Red-team your own copilot: provoke and catch a confabulated IOC, an invented CVE reference and a poisoned retrieval
Human factors lens: the automation conundrum — the better the tool, the worse the operator’s catch rate when it fails. Designing personal “trust-but-verify” checklists that survive deadline pressure.

Topics

  • Automation bias and complacency: the evidence base from aviation, medicine and process control — and its arrival in the SOC
  • Algorithmic authority: why AI output feels more credible than a colleague’s, and when that’s rational
  • Alert fatigue 2.0: AI-generated detections, triage queues and vigilance decrement
  • The out-of-the-loop performance problem: losing situational awareness in systems you nominally supervise
  • Structured verification protocols: second-channel confirmation, provenance checks, dissent-by-design in team review

Exercise

  • Bias exposure lab: work a triage queue where the AI is confidently wrong on two items — will you catch both? Measured, debriefed, re-run
Human factors lens: calibrated trust as a trainable skill — matching confidence to demonstrated reliability, per tool, per task, per context.

Topics

  • Cognitive offloading and skill degradation: what deskilling research says about analysts who never draft the first pass
  • The verification-before-output discipline: reading AI drafts like a hostile reviewer, not a grateful recipient
  • Deliberate practice for security tradecraft: manual-first drills, “AI-shadow” exercises (do it yourself, then diff against the model)
  • Where AI must not be used: evidential chains, legal thresholds, novel intrusion sets, client-attributable judgement calls
  • Keeping CREST-relevant skills current: mapping practice regimes to CPSA/CRT domains

Exercise

  • AI-shadow drill: manual investigation of a log bundle, then a structured diff against the AI’s version — what did you each miss?
Human factors lens: the “use it or lose it” curve — designing a personal practice regime that fits inside a working week.

Topics

  • The governance frame: ISO/IEC 42001 AI management systems, NIST AI RMF, EU AI Act awareness — what lands on an analyst’s desk in practice
  • Accountability when the AI is wrong: logging, provenance and auditability of AI-assisted decisions
  • Writing reports that disclose and defend AI assistance: client, court and regulator audiences
  • Team-level controls: AI-use policies, peer review of AI-assisted output, escalation triggers

Capstone exercise (assessed)

  • Full AI-assisted incident investigation under time pressure: triage, scoping, attribution hypothesis and client-ready summary — with AI errors injected throughout. Pass requires catching the injected errors and producing an auditable decision trail
Human factors lens: debrief using the SanRa Human-AI Teaming Review — what the team delegated, what it verified, what it missed, and what changes on Monday.

CREST Alignment Map

How SAN-101 maps to CREST.

SAN-101 complements — never replaces — CREST examinations. The table below shows the working alignment used in course design. It does not confer CPD credits or formal accreditation.

SAN-101 Component CREST Syllabus Domain Benefit
Module 1 — AI-shaped threat landscape CPSA & CRT: threat awareness, reconnaissance methodology Current-knowledge grounding for examination scenario questions and real engagements
Module 2 — AI tooling & failure modes CPSA: core technical skills; CRT: tooling & technique Competent, sceptical use of the AI tooling now embedded in analyst platforms
Module 3 — Calibrated trust CRT: methodology, quality assurance of findings Fewer false positives escalated; fewer true positives missed; defensible triage
Module 4 — Skill maintenance CREST practitioner → registered → certified career ladder Sustained examination readiness; protection against skill decay between assessments
Module 5 — Governance & capstone CRT: reporting & client communication; CREST code of conduct Auditable reporting practice aligned to member-company quality expectations

Assessment

Assessed like the job, not like a quiz.

The free online edition includes a short knowledge check for learning feedback. It is not a formal certification exam and does not award CPD or (ISC)² credits.

Self-paced modules

Five modules with practice prompts you complete in your own time. Progress is saved in your browser on the free online edition.

Knowledge check

A short scenario quiz at the end of the free course for learning feedback — not an accredited exam.

No CPD / no (ISC)² credits

This edition is free learning content. It is not CPD-accredited and not (ISC)² accredited. Do not claim formal credits from it.

Try It Now

Sample the knowledge check.

Four real questions from the SAN-101 item bank. Answer to see the marking logic.

Q1.An AI copilot summarises an inbound alert and concludes “no further action required.” Your queue is long. The calibrated response is to:

Calibrated trust is not blanket rejection or blanket acceptance. Silent omission is the highest-consequence, lowest-visibility failure mode of AI triage — closure recommendations earn the same structured verification as escalations, using second-channel and provenance checks. (Module 3)

Q2.Which failure mode is most likely when an LLM is asked to enrich an unfamiliar indicator of compromise?

Confabulation is the default failure on low-knowledge queries: the model fills gaps with plausible fabrication, delivered with undiminished confidence. Sycophancy is real but second-order here. This is why provenance checks are mandatory on enrichment output. (Module 2)

Q3.After six months of AI-first drafting, your manual log-analysis speed has measurably dropped. The human factors term and correct countermeasure are:

Deskilling is the predictable cost of never drafting the first pass. The countermeasure is structured: manual-first work on a schedule, then a diff against the model’s version. “Trusting less” is not a trainable behaviour; practice regimes are. (Module 4)

Q4.Under ISO/IEC 42001 and the NIST AI RMF, an AI-assisted incident conclusion is auditable when:

Accountability attaches to people and records, not policies or vendors. An auditable conclusion names the AI contribution, the human verification applied, the deltas, and the accountable owner. (Module 5)

FAQs

Common questions.

Is SAN-101 a CREST examination preparation course?

No — and deliberately so. SAN-101 complements the CREST pathway rather than teaching to an exam. Content is mapped to CPSA and CRT syllabus domains for orientation, but this free edition awards no CPD and is not an exam-prep product.

Is the course itself CREST accredited?

No. The curriculum is mapped to CREST syllabus domains for orientation only. SAN-101 is not currently presented as a CREST-accredited course product, and this free online edition makes no accreditation claim.

Do we need to use specific AI tools to attend?

No. The free online edition runs in your browser. The protocols taught — verification, provenance checking, AI-shadow drills — are tool-agnostic.

Is this course suitable for whole SOC teams?

Yes — private cohorts for teams of 8–16 are the most common booking. Team delivery adds a shared vocabulary for trust calibration and produces a team-level AI-use SOP as a course artefact.

What does it cost?

The online edition is free for now. Request a personal access link and start immediately. Instructor-led team delivery can be quoted separately by email.

How is this different from vendor AI training?

Vendor training teaches you to operate their tool well. SAN-101 teaches you to catch any tool when it is wrong — including the days when the confident, fluent, well-formatted answer is fabricated. Those are different skills, and only one of them protects you.

Start SAN-101 free online.

Get a personal access link, work through five modules, and take the knowledge check — no password and no payment. Bookmark your link to return later.

Get free access link →
Free for now Self-paced Not CPD / not (ISC)² accredited

Want instructor-led delivery for a team? Email ibrahim.mukherjee@icloud.com.